Checking The Configuration; Configuring The Packet Discarding Alarm Function; Establishing The Configuration Task - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
----End

3.7.4 Checking the Configuration

Checking the Configuration of Limiting the Rate of Sending DHCP Messages.
Prerequisite
The configurations of limiting the rate of sending DHCP messages are complete.
Procedure
l
----End

3.8 Configuring the Packet Discarding Alarm Function

An alarm is generated when the number of discarded packets exceeds the threshold.

3.8.1 Establishing the Configuration Task

Establishing the Configuration Task of Packet Discarding Alarm Function.
Applicable Environment
With DHCP snooping configured, the S3700 discards packets sent from an attacker.
3-2
Table 3-2 Relation between the type of attacks and the type of discarded packets
Type of Attacks
Bogus attack
DoS attack by changing the CHADDR field
Attack by sending bogus messages to extend
IP address leases
Attack by sending a large number of DHCP
Request messages and ARP packets
Issue 01 (2011-07-15)
– The alarm threshold for discarded DHCP messages is set.
By default, the function of checking the rate of sending DHCP messages to the DHCP
stack is disabled on an interface; the rate limit of sending DHCP messages to the DHCP
stack is 100 pps; the DHCP message discard alarm is disabled; the alarm threshold
for discarded DHCP messages is 100.
Run the display dhcp snooping global command to check information about global DHCP
snooping.
shows the relation between the type of attacks and the type of discarded packets.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
Type of Discarded Packets
DHCP Reply messages received from
untrusted interfaces
DHCP Request messages whose CHADDR
field does not match the source MAC address
in the frame header
DHCP Request messages that do not match
entries in the binding table
Messages exceeding the rate limit
Table
113

Advertisement

Table of Contents
loading

Table of Contents